Agent skill

Crypto Bom

by cdxgen in cdxgen/cdxgen

Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

Apache-2.0Auto-check passedSecurity

Install Crypto Bom

skills CLI
$ npx skills add cdxgen/cdxgen --skill crypto-bom -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdxgen/cdxgen crypto-bom --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/crypto-bom .claude/skills/crypto-bom && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-bom
GitHub stars
1.1k
Token cost
~1.4k tokens
SKILL.md length
476 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

  • Works in 2 steps: Cryptographic assets do not carry purls.… → Source-derived algorithm components are…
  • Asked for a CBOM
  • SKILL.md covers Generate, What gets inventoried, Auditing the CBOM and Exploring the result, plus 3 more sections
  • Calls java

What it does

Crypto Bom is an agent skill from cdxgen/cdxgen. Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts, and auditing them for weak or deprecated primitives. Use when asked for a CBOM, a cryptographic inventory, post-quantum readiness assessment, crypto algorithm discovery, or a review of certificates and key material in a codebase.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. It works with Java and Linux. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.

When your agent uses it

  • Asked for a CBOM
  • A cryptographic inventory
  • Post-quantum readiness assessment
  • Crypto algorithm discovery

Example prompts

  • “Use the crypto-bom skill to generate a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic…”
  • “/crypto-bom”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Cryptographic assets do not carry purls. That is correct; they are not packages. Do not treat a missing purl as a gap, and never invent one.
  2. Source-derived algorithm components are constrained to stay validator-safe: cdxgen emits only algorithms it can map to a known OID. An…

What it can do on your machine

Read from SKILL.md and the folder at commit e256966. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cdxgen.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Bom loads about 1.4k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cdxgen/cdxgen at commit e256966, republished under its Apache-2.0 licence (© cdxgen). 476 words, ~1,377 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-bom/SKILL.md (or your agent's skills folder).
name
crypto-bom
description
Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts, and auditing them for weak or deprecated primitives. Use when asked for a CBOM, a cryptographic inventory, post-quantum readiness assessment, crypto algorithm discovery, or a review of certificates and key material in a codebase.

Cryptographic BOM

Use this skill when the user wants to know what cryptography a codebase or host actually uses — for post-quantum migration planning, crypto policy compliance, or finding weak primitives.

Read reference/safety.md first. CBOM source analysis uses the atom companion, which needs no JDK on the native-binary platforms (linux-amd64, linux-arm64 glibc, linux-amd64-musl, darwin-arm64, windows-amd64). Only the jar-based triples (darwin-amd64, windows-arm64, linux-arm64-musl) require Java >= 23 and fail silently below it, so verify java -version there before interpreting a thin CBOM.

Generate

bash
cbom -o /absolute/path/to/cbom.json /absolute/path/to/project

The cbom command is not merely an alias with a flag. Invoking it sets:

SettingValue
--include-cryptoon
--evidenceon
--deepon
--spec-version1.7, unless you pass one yourself

Two combinations are rejected, not silently ignored:

  • cbom --component-type <t> — use cdxgen --include-crypto instead when you need component-type filtering.
  • cbom -t os — crypto evidence collection analyses source with atom, which is meaningless and extremely slow against an OS inventory. Use obom for operating-system installations (see os-hardware-inventory).

The equivalent explicit invocation, when you want to vary one part:

bash
cdxgen --include-crypto --evidence --deep \
  -o /absolute/path/to/cbom.json /absolute/path/to/project

What gets inventoried

  • cryptographic-asset components for algorithms, certificates, keys, and protocols
  • certificates and trusted key material discovered in the tree or host
  • source-derived algorithm inventory from JavaScript and TypeScript via lightweight AST analysis

Note two modelling facts that surprise people:

  1. Cryptographic assets do not carry purls. That is correct; they are not packages. Do not treat a missing purl as a gap, and never invent one.
  2. Source-derived algorithm components are constrained to stay validator-safe: cdxgen emits only algorithms it can map to a known OID. An algorithm you can see in the source but not in the CBOM was most likely unmappable, not missed.
Show full SKILL.md (204 more words)Show less

Auditing the CBOM

bash
cbom -o /absolute/path/to/cbom.json /absolute/path/to/project \
  --bom-audit --bom-audit-categories cbom

The cbom category alias enables both rule sets:

CategoryChecks
cbom-securityWeak or deprecated algorithms, insecure cipher modes, insufficient key sizes, outdated protocol versions
cbom-compliancePolicy and standards conformance of the crypto inventory

crypto-bom works as an alias for the same pair.

Audit an existing CBOM after the fact:

bash
cdx-audit --bom /absolute/path/to/cbom.json --direct-bom-audit --categories cbom

Exploring the result

In cdxi (see bom-explore):

  • .cryptos — the full cryptographic asset list
  • .sourcecryptos — only the JavaScript/TypeScript source-derived algorithm components
  • .trusted — trusted keys and certificates

Reach for .sourcecryptos when the user's question is about code-level algorithm usage rather than the certificates and keys shipped alongside it.

Crypto usage in Go, with data flow

For Go projects, evinse can trace crypto data flow rather than just presence — which values reach a cryptographic operation:

bash
cdxgen -t go -o /absolute/path/to/bom.json /absolute/path/to/project
evinse -i /absolute/path/to/bom.json -o /absolute/path/to/bom.crypto.json \
  -l go --with-data-flow \
  --golem-dataflow crypto --golem-dataflow-pattern-packs crypto \
  /absolute/path/to/project

Prioritize components carrying cdx:golem:cryptoDataFlow=true and cdx:golem:cryptoDataFlowCount, then pivot on the rendered cryptographic-asset algorithms. See bom-evidence for the full Golem surface.

Never surface raw plaintext, ciphertext, key material, or embedded file contents from Golem output. Review through the emitted cdx:golem:* counts, categories, taint kinds, and algorithm/OID pivots.

Runtime crypto observation

To see crypto actually exercised at runtime rather than inferred from source, tracebom has dedicated probes:

bash
tracebom --cmd "node app.js" --trace-crypto --crypto-probe-mode <mode> \
  -o /absolute/path/to/trace-cbom.json

See runtime-trace-bom.

Reference

© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-plugin/skills/crypto-bom of cdxgen/cdxgen.

Open the folder on GitHubat commit e256966

Compare with similar skills

Crypto Bom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Bom compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Bom this skillcdxgen/cdxgen1.1k—~1.4kAutomated safety check: PassApache-2.0
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Azure Security Keyvault Keys Javamicrosoft/skills3.1k5 repos~2.9kAutomated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Implementing Sigstore For Software Signingmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Azure Key Vault Keys Java SDK for cryptographic key management.

    3.1k GitHub starsUsed in 5 repos~2.9k tokens
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Implementing Sigstore For Software Signing

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

    446 GitHub stars~885 tokensUpdated yesterday
    SecurityAuto-check passed

More from cdxgen/cdxgen

All 17 skills in this repo
  • AI Bom

    cdxgen/cdxgen

    Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…

    1.1k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Bom Signing

    cdxgen/cdxgen

    Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: warnings

Works with

Categories

Questions about Crypto Bom

What does Crypto Bom do?

Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…. Crypto Bom is an agent skill from cdxgen/cdxgen. Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts, and auditing them for weak or deprecated primitives.

When should I use Crypto Bom?

Crypto Bom fits situations like: asked for a CBOM; A cryptographic inventory; post-quantum readiness assessment; crypto algorithm discovery.

How do I install Crypto Bom in Claude Code?

Run `npx skills add cdxgen/cdxgen --skill crypto-bom -a claude-code`. Or copy the skill folder (claude-plugin/skills/crypto-bom in cdxgen/cdxgen) into .claude/skills/crypto-bom in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Bom in Codex?

Run `npx skills add cdxgen/cdxgen --skill crypto-bom -a codex`. Or copy the skill folder (claude-plugin/skills/crypto-bom in cdxgen/cdxgen) into .agents/skills/crypto-bom in your project. Codex loads it when a task matches its description.

Can I use Crypto Bom in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill crypto-bom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-bom, .gemini/skills/crypto-bom, .github/skills/crypto-bom and .opencode/skills/crypto-bom in your project.

What does Crypto Bom need to run?

Going by SKILL.md and its folder, Crypto Bom needs the command-line tools its instructions call (java).

Does Crypto Bom access the network?

SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.

Is Crypto Bom safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crypto Bom use?

Crypto Bom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Bom use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crypto Bom?

Skills that share tags, products or a category with Crypto Bom: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Constant-Time Analysis (trailofbits/skills, 7.4k stars), Azure Security Keyvault Keys Java (microsoft/skills, 3.1k stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Bom?

cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.